Browse Source

init: do not hook prerouting SYN,ACK in desync mode

pull/53/head
bol-van 5 years ago
parent
commit
e04037952d
  1. 4
      init.d/openwrt/functions
  2. 4
      init.d/sysv/functions

4
init.d/openwrt/functions

@ -304,13 +304,9 @@ zapret_apply_firewall()
fw_nfqws_post "--dport 80" "--dport 80" $QNUM
;;
nfqws_all_desync|nfqws_hostlist_desync)
rule="-m multiport --sports 80,443 $synack"
fw_nfqws_pre "$rule" "$rule" $QNUM
fw_nfqws_post "$desync" "$desync" $QNUM
;;
nfqws_ipset_desync)
rule="-m multiport --sports 80,443 $synack"
fw_nfqws_pre "$rule $ipset_zapret src" "$rule $ipset_zapret6 src" $QNUM
fw_nfqws_post "$desync $ipset_zapret dst" "$desync $ipset_zapret6 dst" $QNUM
;;
custom)

4
init.d/sysv/functions

@ -423,13 +423,9 @@ zapret_do_firewall()
fw_nfqws_post $1 "--dport 80" "--dport 80" $QNUM
;;
nfqws_all_desync|nfqws_hostlist_desync)
rule="-m multiport --sports 80,443 $synack"
fw_nfqws_pre $1 "$rule" "$rule" $QNUM
fw_nfqws_post $1 "$desync" "$desync" $QNUM
;;
nfqws_ipset_desync)
rule="-m multiport --sports 80,443 $synack"
fw_nfqws_pre $1 "$rule $ipset_zapret src" "$rule $ipset_zapret6 src" $QNUM
fw_nfqws_post $1 "$desync $ipset_zapret dst" "$desync $ipset_zapret6 dst" $QNUM
;;
custom)

Loading…
Cancel
Save